Public sector digitalisation
IDA's position
IDA believes that digitalisation is a positive force, provided it is implemented responsibly and intelligently. This means ensuring that the foundations are sound.
In fact, the standards must be exceptionally high when dealing with citizens' personal identification numbers (CPR numbers), health records, tax information, salary data and other highly sensitive information.
Over the years, Denmark's public sector has pursued a number of digitalisation strategies with remarkable ambition and breadth. As a result, Denmark consistently ranks among the world's most digitalised public sectors.
We take pride in the fact that delegations from around the world visit Denmark to learn from our approach to digital government and public services.
Overall, this is a success story, and as an organisation representing engineering, science and technology professionals, IDA welcomes the public sector's commitment to technological innovation.
However, we must be exceptionally careful and highly competent when digitalising public services. Above all, we must recognise a fundamental principle: citizens own their personal data and should be able to grant authorities access to it only through informed and active consent.
Better public-sector IT projects – seven recommendations from IDA
At IDA, we want to help ensure that current and future digitalisation initiatives become more effective, sustainable and successful.
In other words, public-sector digitalisation must be built on the right skills, financial frameworks, contractual arrangements, organisational culture, system architecture and technical foundations.
Drawing on engineering and scientific expertise, IDA has identified the areas where action is likely to deliver the greatest value and impact.
IDA recommends the following:
- Ensure the right skills and expertise are involved from the outset.
- Adapt financial frameworks to keep pace with technological development.
- Challenge the existing zero-error culture.
- Break projects and deliverables into smaller components and adopt more agile development methods.
- Improve contracts and strengthen supplier management.
- Take greater responsibility for IT architecture.
- Give appropriate weight to technical considerations when making decisions.
IDA's concerns about a public contact register
In early 2019, the Ministry of Public Sector Innovation proposed legislation to establish a public contact register containing citizens' telephone numbers and email addresses.
The proposal would provide the legal basis for collecting, maintaining and using contact information.
The information would be used by public authorities to remind citizens about appointments and deadlines, and to contact them regarding specific cases or services. As Digital Post (formerly e-Boks) already contains citizens' CPR numbers, email addresses and mobile phone numbers could potentially be linked directly to personal identification records.
IDA has reservations about such a register.
In our view, the proposal could mean that citizens who believed they were providing their contact details solely to Digital Post would, in practice, have their information transferred to a new central government database. This would enable a range of public authorities to contact individuals, even if they never intended to share their details beyond their original purpose.
The Danish Data Protection Agency must be further strengthened
In spring 2017, IDA and a number of other organisations sent an open letter to the Danish Government calling for a significant strengthening of the Danish Data Protection Agency (Datatilsynet).
In 2018, the Government increased the Agency's budget by approximately 50 per cent. While IDA recognises that this was a step in the right direction, it remains far from sufficient.
The introduction of the General Data Protection Regulation (GDPR) and Denmark's Data Protection Act has given the Agency a number of new responsibilities. GDPR alone introduced several additional duties and enforcement obligations.
At the same time, the Agency plays a crucial role in maintaining public confidence that Denmark's digitalisation efforts are both secure and effective.
The Agency has stated that it identifies issues during almost every inspection it carries out. In 2016, however, it only had the resources to complete 51 inspections during the year. Furthermore, its mandate remains too limited to effectively require public authorities, in particular, to address deficiencies.
IDA recognises that significantly strengthening the Agency – and continuously reviewing and expanding its capabilities as digitalisation evolves – comes at a cost.
However, the cost of weakened public trust, the exposure of sensitive personal information, and inefficiencies in organisations and public authorities that repeatedly spend resources addressing the same issues without adequate guidance is far greater.
If GDPR and Denmark's Data Protection Act are to be implemented and enforced effectively, a strong and well-resourced Danish Data Protection Agency is essential.
IDA will therefore continue to emphasise the importance of a strong and independent supervisory authority.
Read the open letter on strengthening the Danish Data Protection Agency
Many requirements must be met before IDA can support the National Genome Centre
On 1 March 2018, IDA and several other organisations sent an open letter to the Minister for Health regarding plans to establish a National Genome Centre. The letter outlined a number of requirements that IDA considers essential.
Consent
Citizens should have the right to provide informed consent before sensitive genetic information is transferred to the National Genome Centre, where it may be combined with data from Danish public registers.
Consent should be based on clear information about:
- what data will be stored;
- whether the data can be linked back to the individual; and
- the purposes for which the data may be used.
If any of these conditions change, the original consent should no longer be considered valid.
Security
Genetic data held by the National Genome Centre should be stored securely and, wherever possible, fully anonymised. Genetic information linked to CPR numbers presents a significant information security risk, including where pseudonymisation techniques are used. Anonymous storage does not prevent future analysis alongside other anonymised datasets.
Transparency
Citizens deserve full transparency regarding all intended uses of the National Genome Centre, including both commercial and governmental purposes.
If the Centre's objectives are expanded or altered, or if its data is used for new purposes, existing consent should remain valid only for the purposes originally approved.
Any changes to the data being stored, the possibility of identifying individuals, or the use of data for new purposes should require renewed consent following clear information about those changes.
Following the introduction of the legislation, questions were raised about whether the police could gain access to information held by the National Genome Centre.
During the first parliamentary reading of the bill, the Minister stated that this would not be possible. However, several experts, including representatives of the Danish National Police, later argued that access could be granted under existing criminal procedure legislation following a court order.
It is essential that Parliament examines this issue thoroughly before the Centre is established.
Public trust in personalised medicine and genetic research could be seriously undermined if the National Genome Centre were effectively to function as a searchable DNA database for law enforcement purposes.